Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Stardust was a StarBasic macro sample reported by Kaspersky in May 2006—not a spreading OpenOffice outbreak. Kaspersky initially described it as theoretically capable of infecting StarOffice or OpenOffice, but OpenOffice.org disputed that it could self-replicate under default settings, and Kaspersky later said the sample was too broken to replicate.

What was the Stardust virus?

On May 30, 2006, Kaspersky researcher Konstantin Sapronov reported a sample named Virus.StarOffice.Stardust.a, written in StarBasic, the macro language used by StarOffice and OpenOffice. He called it “the first virus I know of which is theoretically capable of infecting StarOffice and/ or OpenOffice.” Kaspersky’s initial report described a macro that downloaded an image from the Internet and opened it in a new document.

That account described what the sample was intended or theoretically able to do; it did not establish that it had infected users’ computers. A contemporary Computerworld report said Kaspersky had not seen it used to infect computers. The report described it as contained in a StarOffice macro document and aimed at text documents with .sxw extensions and templates with .stw extensions. Computerworld’s May 30, 2006 report also relayed that code changes could make it affect OpenOffice 2.0—a theoretical possibility, not evidence of a successful OpenOffice infection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Could Stardust infect OpenOffice?

Kaspersky’s first announcement used cautious, theoretical language about StarOffice and/or OpenOffice. OpenOffice.org responded that the demonstration did not establish a self-replicating virus under the suite’s default settings: a user had to approve running the macro. The project said the issue did not require a software patch. Its statement framed the sample as a proof of concept illustrating the known risk of powerful macro languages. OpenOffice.org project statement

#1 Best Overall

On June 3, 2006, Kaspersky researcher Costin Raiu clarified that Stardust had severe programming errors and could not replicate. His later assessment narrowed the initial report: regardless of the theoretical capability described at first, this sample was broken and did not function as a replicating virus. Kaspersky’s follow-up clarification

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Did Stardust spread, and did users need a patch?

No reported evidence in the contemporary accounts showed Stardust spreading in the wild. Computerworld reported that the sample had not been used to infect computers, and Kaspersky later said it could not replicate. OpenOffice.org therefore said no patch was needed for this proof of concept. That conclusion concerns the 2006 sample and the software behavior discussed at the time; it is not a security assessment of current office software.

Contemporary coverage relayed the project’s general advice not to accept files from unknown sources. That is historical guidance from the 2006 incident, not a current product-specific recommendation. Linux.com’s contemporary coverage

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.